SOCLYDE logo
Current languageEN
Cybersecurity newsData breachSecurity incident

Belnet: emails copied after a fortinet flaw

Belnet confirms incoming emails were copied and FileSender transfers may have been accessible after a Fortinet zero-day was exploited.

By Soclyde Team

A technician reviews a messaging service incident log in a quiet office

In summary

  • Belnet detected an intrusion on September 24, 2026, involving a zero-day vulnerability in Fortinet technology.
  • Incoming emails received between July 22 and the morning of September 25 were copied to external infrastructure.
  • FileSender and FedSender links may have allowed access to files; password-protected or authenticated transfers are excluded under stated conditions.

Explore next

Soclyde resources

Article contents

Belnet, Belgium’s national network for higher education, research and public services, detected a security and privacy incident in its infrastructure on September 24, 2026. The organisation says the intrusion resulted from exploitation of a zero-day vulnerability affecting technology supplied by Fortinet.

Belnet says it fixed the vulnerability on September 25 at 08:10, engaged the Centre for Cybersecurity Belgium and informed the competent authorities. Fortinet published advisory FG-IR-26-175 about the vulnerability. Belnet’s investigation continues to establish the incident’s scope.

Incoming emails were copied

Belnet established that emails processed by the affected infrastructure between July 22, 2026 and the morning of September 25 were copied and transferred to external infrastructure. The scope includes incoming messages addressed to domains owned by Belnet, along with sender details, message content and attachments.

The organisation has informed its customers and says it is continuing to identify other potentially affected parties. People involved should rely on direct communications from Belnet for details about their own situation.

Download links generated and sent directly by FileSender and FedSender during the affected period may also have allowed access to associated files. As a precaution, Belnet disabled links that were still active and transfers created during that period on September 29. Senders and recipients received an automatic notification.

Belnet says password-protected or authenticated transfers are not affected in this way, provided the password was not included in an upload comment. A sender who still needs to share a file should create a new transfer; a recipient should ask the sender to create it again.

Guestroam accounts and impersonation risk

Guestroam accounts generated through Belnet’s service are also included in the published scope. Copied emails and potentially accessible files may contain professional or personal context. This creates a risk of more convincing phishing, but does not prove that a fraud campaign has already used the data.

Verify unexpected requests through a channel you already know, especially if they refer to a conversation, transfer or Belnet account. Do not share a password, authentication code or banking detail in response to an unexpected email or call.

Steps for organisations

Institutions using Belnet services should review emails received and transfers created between July 22 and September 25. Identify sensitive files that may have been shared by link, check whether each transfer met Belnet’s stated protection conditions, and ask the sender to recreate any sharing that is still needed.

Fortinet administrators should consult advisory FG-IR-26-175 to determine whether their equipment and version are affected, then apply the vendor’s security measures. Fixing the vulnerability and assessing potentially exposed emails and files are separate tasks.

The Soclyde connection

This incident concerns email and file-transfer infrastructure; Soclyde does not protect Belnet, FileSender or FedSender. Soclyde is a local-first password and access manager: its encrypted vault helps a user organise their own credentials on their devices. It does not replace email system security or controls over file transfers.

Takeaway

Belnet confirms incoming emails were copied between July 22 and September 25, and that some FileSender and FedSender links may have allowed access to files. Guestroam accounts are also in scope. Institutions should review their communications and follow Belnet’s and Fortinet’s guidance.

To organise your team’s access details, read our guide to local-first password managers.

Frequently asked questions

Which emails were copied?

Belnet says incoming emails addressed to its domains between July 22 and the morning of September 25, 2026 were copied. This includes sender details, message content and attachments. Its investigation continues to determine whether other parties were affected.

Are FileSender and FedSender files involved?

Links generated and sent directly by FileSender or FedSender during this period may have allowed access to associated files. Belnet says password-protected or authenticated transfers are not affected in this way, unless the password was included in an upload comment.

What if a transfer was disabled?

Belnet disabled affected transfers that were still active on September 29. Senders should create a new transfer if the files still need to be shared; recipients should ask the sender to create it again. Also verify unusual requests that refer to the context of a copied email.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading